'Iceman' pleads guilty to massive company hacks

Prolific hacker shows bank vulnerability.

A former security analyst turned hacker, yesterday pleaded guilty to breaking into numerous financial institutions and card-processing networks and stealing credit card and identity data on hundreds of thousands of individuals.

The guilty plea came after the accused, Max Ray Butler, had requested nearly a dozen extensions for time to file pre-trial motions after his arrest in September 2007 on three counts of wire fraud and two counts of transferring stolen identity information.

The charges carry a maximum of 40 years in prison and a $1.5 million (£912,000) fine. It's possible that Butler will receive a substantially lighter sentence by agreeing to plead guilty.

Butler, 37, was arrested in San Francisco, but the case is being heard in Pittsburgh because one of his accomplices who is cooperating with authorities in the case is based in Pennsylvania.

Butler has already served an 18-month prison term after he was convicted in May 2001 on charges of breaking into and accessing US Department of Defense computers. He was also part of a group of four individuals that was investigated by the FBI and the US Secret Service in January 2004 for compromising software code in the Half Life video game.

Court documents filed in connection with Butler's most recent arrest describe what appears to have been an elaborate scheme and an equally painstaking 16-month effort to nab him.

The thefts and break-ins to which Butler pleaded guilty took place between June 2005 and September 2007. During that time, Butler, who used the online nicknames "Iceman," "Digits," "Darkest" and "Aphex," broke into the networks of numerous institutions, including Citibank and the Pentagon Federal Credit Union, and stole data on hundreds of thousands of credit cards.

Butler then he sold the data to several of his accomplices via a website called Cardersmarket that he set up in 2005 along with another individual named Christopher Aragon. According to the court documents, Aragon would manufacture or re-encode credit cards with the stolen card information provided by Butler. Aragon and his "crew" would use the cards to fraudulently purchase thousands of dollars worth of merchandise at retailers such as Wal-Mart and Dillard's.

The merchandise would then be resold by others, including Aragon's wife, through venues such as eBay. Butler would receive a cut from the proceeds of such sales typically through pre-paid Green Dot credit cards.

The 6-foot, 5-inch, often pony-tailed Butler, would carry out his hacking activity from multiple locations, including hotel rooms and apartments in San Francisco that he would rent under the name Daniel Chance.

Two of Butler's accomplices, who were arrested before him, described how they along with Butler and Aragon would rent hotel rooms four days at a time to hack into nearby businesses. The group would use an "expensive, high-powered antenna" to intercept wireless communications and break into networks, the court documents said. Butler would often gain access to full profiles and PIN numbers of account holders via such intrusions.

One of them described how Butler had rigged his computers so he could permanently wipe out any incriminating evidence on them with just two keystrokes.

Though Butler appears to have taken what he thought were fairly elaborate measures to conceal his activities, what he didn't know was that federal authorities had two informants posing as members of Cardersmarket. One of them, identified in court documents only as CI#2, was given administrative responsibilities for the Cardersmarket website by Butler. The two informants gathered detailed information on the activities of the group and against Butler.

On one occasion, for instance, one of the informants was asked by a Secret Service agent to buy 23 stolen credit cards from Butler for $480. On another occasion the same informant was asked to purchase an additional 38 cards for $456. The eGold account to which the money was transferred and the computers that were used in the transactions were later traced back to Butler.

Despite using various nicknames in an apparent attempt to conceal his identity, Butler himself provided federal authorities with direct information linking his true identity with the assumed names.

In one intercepted chat communication between Butler and CI#2, Butler says "so obviously I am digits also. Might as well say it straight since I blew cover in ICQ (talking about our forum)," he says. "It is a pain in the ass trying to keep that separate from people I know and trust and like such as yourself," he says.

After Aragon's arrest in August 2007, Butler shut down Cardersmarket with a message to members that he was "retiring." The forum came back up shortly thereafter under the management of a supposedly new administrator who in fact was Butler himself. At the time of his arrest the Cardersmarket website was still up.


What are your views on this subject? Use the form below to post a comment on this article up to 500 characters.


Characters remaining: 500

Add your commentComments

JOHNNY69 | Published: 18:43 GMT, 02 July 2009

With obvious intellect like he has, why not apply it to an honest living. Is the "Rush" really worth it?

DanTe | Published: 15:03 GMT, 01 July 2009

Put an electric collar on the scum and have the CIA put him to work in a slave pen hacking into foreign governments.

Related Security news

DNS hole leads to more DDoS attacks

Badly configured cable modems cause headaches for security experts.

Apple Safari gets security fix in update

Windows users get patch that Leopard users received more than two months ago

Fortinet detects increase in malware levels

Four-fold increase since September

Flash flaw affects nearly every web user say researchers

Adobe vulnerability a major risk



Email this article to a friend or colleague:


PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Database security: Preventing enterprise data leaks at the source

IDC discusses the growing internal threats to business information, the impact of government regulations on the protection of data, and how enterprises must adopt database security best practices...

Download Whitepaper

Service-oriented security

SOA has become an integral part of enterprise software by providing a framework to efficiently develop software as services that is easily sharable, reusable, and integrated. No where is the need more apparent than in the Identity Management space. Welcome to the age of Service-Oriented Security (SOS).

Download Whitepaper

Data protection prospective vendor checklist

Organisations need a way to map business needs against all these challenges in procuring a technical solution. To help, SANS has developed the following Prospective Vendor Checklist.

Download Whitepaper

Best practices for optimising performance and availability in virtual infrastructures

Many IT administrators have already learned the hard way that managing the performance and availability of services built on virtualisation technologies can be difficult, if not impossible at times. All too often, early adopters of virtualisation have struggled with limited technology features and stability constraints, while learning new ways to effectively manage capacity requirements.

Download Whitepaper

Techworld UK - Technology - Business

COLT White Paper

Are all VoIP services the same?

Questions to ask your service provider to ensure you get the VoIP service you need
With careful choice of partner, your business can have all the advantages of VoIP access - reduced costs, flexibility and simplicity - without the drawbacks.
This white paper is your guide to ensure you get right the VoIP service and details the pitfalls which businesses would do well to avoid.

Download white paper
BMC

Unlock the hidden IT opportunities in troubled economic times

How to take advantage of the growth potential that will occur when the economy rebounds
With the right approach, processes, and technology, it’s possible for IT to provide higher-quality services for a lower cost, while also empowering the business to position itself to take advantage of the growth potential that will occur when the economy rebounds.

Download white paper

Webcast: IT Financial Management: Cost Optimisation for Efficiency and Agility.
On Demand Webcast
Join this webcast to learn about the techniques and technologies that can help you prove the value of IT to the business by understanding the true cost of today's IT services and those that will be necessary to deliver future success.

Register Today

Site Map

IDG Network

* *